Comes installed with major security distributions including BackTrack and Matriux

Introduction

Free and Open Source Browser based Security Framework

Description

Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.

Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.

Licensing

OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.

What is OWASP Mantra?

OWASP Mantra provides:

A web application security testing framework built on top of a browser.

Supports Windows, Linux(both 32 and 64 bit) and Macintosh.

Can work with other software like ZAP using built in proxy management function which makes it much more convenient.

As of now, the priorities are:
Create an ecosystem for hackers based on browser
To bring the attention of security people to the potential of a browser based security platform
Provide easy to use and portable platform for demonstrating common web based attacks( read training )
To associate with other security tools/products to make a better environment. Eg:
It can be a nice addition to OWASP Live CD
It can be used to solve basic levels of CTF contests
It can associate with projects like DVWA to showcase attacks
It can bring functions like crawler, SQL injection scanner etc by installing extensions.

Involvement in the development and promotion of OWASP Mantra is actively encouraged!
You do not have to be a security expert in order to contribute.

PROJECT INFOWhat does this OWASP project offer you?

RELEASE(S) INFOWhat releases are available for this project?

what

is this project?

Name: OWASP Mantra - Security Framework (home page)

Purpose: Mantra is a security framework which can be very helpful in performing all the five phases of attacks including reconnaissance, scanning and enumeration, gaining access, escalation of privileges,maintaining access, and covering tracks. Apart from that it also contains a set of tools targeted for web developers and code debuggers which makes it handy for both offensive security and defensive security related tasks.